Control in Practice.
The control by the Polish Data Protection Authority is usually announced a few days (7 days) prior to the arrival of the inspectors. Therefore, the entrepreneur has time to prepare calmly for it. The notification of the control most often specifies its scope and information on what needs to be prepared. The control is conducted as part of the control plan, which is a document
Receive a package of free GDPR guides and micro-trainings
If the control reveals any deficiencies, the inspector will request the Polish Data Protection Authority to issue an administrative decision ordering their removal. The outcome of the control may also be the initiation of administrative proceedings, as a result of which a fine of up to PLN 200,000 may be imposed on the entrepreneur, and PLN 50,000 on an individual.
Notification of Control by the Polish Data Protection Authority and…
We have received a notification of an inspection. What now? First and foremost, do not panic! Even if we do not have any documentation, a Data Protection Officer, or trained staff, we can still save ourselves, especially if our business is small (employing fewer than 50 employees). It is essential to create documentation for personal data protection. Of course, inspectors will notice that the date of the document is later than the notification of the inspection, but it will always look better than having nothing at all. After receiving the notification of the inspection, there may be ideas to create documentation with a backdated timestamp. However, we strongly advise against such practices. Falsifying company documentation can lead to liability under the provisions of the Penal Code and the Fiscal Penal Code, which can have truly serious consequences.
Remaining activities of the Polish DPA.
In addition to conducting inspections and issuing decisions, the Polish DPA is responsible for the registration of personal data sets that are subject to registration. The register is maintained for the transparency of data processing, allowing any interested party to check which company manages which set of data. Furthermore, an important task of the Polish DPA is to promote knowledge about personal data protection – it conducts educational activities for this purpose – as well as to advocate for necessary changes in the law regarding data protection.
In conclusion…
In summary, an inspection is nothing to be afraid of if we meet the requirements of the regulation and the Personal Data Protection Act. However, it can cost us dearly if we do absolutely nothing to ensure the security of the data we process. To know how to do this, it is worth taking a closer look at the educational activities of the Polish DPA, and of course, reading our blog!


